Malware

MSIL/Kryptik.AARC (file analysis)

Malware Removal

The MSIL/Kryptik.AARC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AARC virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.AARC?


File Info:

crc32: 54FFD26F
md5: 13a8ca17d4b77f65052f928f39ef46b8
name: 13A8CA17D4B77F65052F928F39EF46B8.mlw
sha1: 3c61930f2dfcbd798a063137629ef33f222855ca
sha256: 5a38b12ebce12dde580da36ee1b4a5c0387f9e81f7f738c278b60d5781dad6eb
sha512: df7938528522073cbb95c3aee4c2c24abf519c87190f35650a41979601c6611e0c0c6cfb3208f71bfcbba4ce45ba0af65ddf5ca87d68c93848f76ddb84fdacce
ssdeep: 6144:tDmMtfUeAIQHuA36cdPqaQUVTI/CK5vyUin:t9eeAItC66SaRIqAv0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) 2020 Discord Inc. All rights reserved.
Assembly Version: 0.0.52.0
InternalName: Pkstfvgdp.exe
FileVersion: 0.0.52.0
CompanyName: Discord Inc.
LegalTrademarks:
Comments: Discord - https://discord.com/
ProductName: Discord - https://discord.com/
ProductVersion: 0.0.52.0
FileDescription: Discord - https://discord.com/
OriginalFilename: Pkstfvgdp.exe

MSIL/Kryptik.AARC also known as:

K7AntiVirusTrojan ( 0057ba031 )
DrWebTrojan.PackedNET.691
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforBackdoor.MSIL.NanoBot.gen
AlibabaBackdoor:MSIL/NanoBot.c7eca8d0
K7GWTrojan ( 0057ba031 )
Cybereasonmalicious.f2dfcb
CyrenW32/MSIL_Kryptik.ECD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AARC
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderTrojan.GenericKD.36808313
MicroWorld-eScanTrojan.GenericKD.36808313
Ad-AwareTrojan.GenericKD.36808313
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.earct@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.grp
FireEyeGeneric.mg.13a8ca17d4b77f65
EmsisoftTrojan.Crypt (A)
AviraTR/AD.Chapak.ibtfv
eGambitPE.Heur.InvalidSig
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla!MTB
AegisLabTrojan.MSIL.Vobfus.4!c
GDataTrojan.GenericKD.36808313
AhnLab-V3Trojan/Win.Generic.C4444150
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.MSIL
PandaTrj/GdSda.A
RisingBackdoor.NanoBot!8.28C (CLOUD)
IkarusTrojan.MSIL.Inject
FortinetMSIL/GenKryptik.FEQD!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.AARC?

MSIL/Kryptik.AARC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment